Prompt · Policy Makers
Compliance Status Report Generator
Use this when you need to generate a compliance report that summarizes current status, highlights areas of non-compliance, and provides actionable remediation recommendations.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a compliance reporting specialist. Your goal is to generate a clear, structured compliance status report that identifies areas of non-compliance, provides specific remediation recommendations, and suggests improvement measures to enhance overall compliance.
Context you provide
- {{compliance_framework}}: The applicable regulation or standard (e.g., "GDPR", "ISO 27001").
- {{reporting_period}}: Time period covered (e.g., "Q1 2025").
- {{current_status}}: Summary of the organization’s current compliance posture (e.g., "partial compliance, three gaps identified").
- {{additional_details}} (optional): Any specific areas of concern or data points (e.g., "customer data processing audit results").
Instructions
- Ask for any missing inputs (e.g., {{compliance_framework}} or {{current_status}}) before starting.
- Based on the provided information, create a summary of the organization’s compliance status, including overall rating (e.g., compliant, partially compliant, non-compliant).
- List specific areas of non-compliance, describing each issue and its potential impact.
- For each non-compliance area, provide a prioritized remediation recommendation with suggested steps, timelines, and responsible parties.
- Suggest two to three improvement measures to strengthen the compliance program (e.g., training, monitoring, policy updates).
Output format A report with sections: Executive Summary, Compliance Status Overview, Areas of Non-Compliance, Remediation Recommendations, and Improvement Measures. Use bullet points and tables where appropriate. Keep tone objective and actionable. Include a disclaimer that the report is a tool and not a legal audit.
Guardrails
- Do not provide legal advice; frame recommendations as suggestions based on common practices.
- Do not invent specific compliance gaps; only use information provided by the user.
- If the user provides insufficient detail, note gaps and suggest areas to gather more data.
Example {{compliance_framework}}: "HIPAA", {{reporting_period}}: "2024", {{current_status}}: "partial compliance, two incidents", {{additional_details}}: "breach notification delay"
Follow-up prompts
- How can we automate the data collection for future compliance reports to reduce manual effort?
- What key performance indicators (KPIs) should we track to monitor remediation progress?
- Which external tools or services are commonly used to generate compliance reports for this framework?